# Trending CVE URIs - literal substring match
# Source: https://hub-data.crowdsec.net/web/trendy_cves_uris.json
# CrowdSec filter: http_path contains JsonExtract(#, "uri")
# Snapshot date: 2026-07-27

# CVE-2024-3400
/global-protect/login.esp
# CVE-2024-3272
/cgi-bin/nas_sharing.cgi
# CVE-2018-12031
/server/node_upgrade_srv.js
# CVE-2021-36380
/cgi/networkdiag.cgi
# CVE-2021-3129
/_ignition/execute-solution
# CVE-2020-27866
/setup.cgi
# CVE-2024-4040
/webinterface/login.html
# CVE-2024-4040
/webinterface/
# CVE-2024-24919
/clients/mycrl
# CVE-2024-4577
?%ad
# CVE-2024-5806
/guestaccess.aspx
# CVE-2024-0769
/hedwig.cgi
# CVE-2019-8318
/hnap1/
# CVE-2024-8190
/gsb/datetime.php
# CVE-2021-33044
/rpc2_login
# CVE-2024-8963
index.php%3f.php/
# CVE-2025-0108
/unauth/%252e%252e/php/
# CVE-2025-31324
/developmentserver/metadatauploader
# CVE-2024-38653
/mdm/checkin
# CVE-2025-34509
/sitecore/api/ssc/auth/login
# CVE-2023-6549
/nf/auth/startwebview.do
# CVE-2025-5777
/p/u/doauthentication.do
# CVE-2025-25257
/api/fabric/device/status
# CVE-2025-53770
/_layouts/15/toolpane.aspx
# CVE-2023-0669
/goanywhere/lic/accept
# CVE-2024-0204
/goanywhere/images/..
# CVE-2025-64446
/api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi
# CVE-2025-59718
/remote/saml/login
# CVE-2025-40553
/helpdesk/WebObjects/Helpdesk.woa/ajax/9.7.43.0.0.0.4.3.7.0.7.1.1.1
# CVE-2025-40553
/helpdesk/WebObjects/Helpdesk.woa/ajax/2.0.7.1.1.1
# CVE-2025-40552
/helpdesk/WebObjects/Helpdesk.woa/wo/
# CVE-2026-20127
/reports/data/opt/data/containers/config/data-collection-agent/.dca
# CVE-2026-63030
/wp-json/batch/v1
